Translate

Friday, February 18, 2011

TLS for everyone

I've been under the blogger radar for a few weeks now.  Mostly due to stress at my job.  Can't go into it other than to say I'm basically the NSA for my employer.

I just want to make a call to the IT industry.  If you are a sys-admin, mail-admin, IT admin, CIO, software vendor, or have any influence with someone that is...
Implement TLS on your mail server!

A whole lot of head and heartache could be alleviated if everyone just would. 

For the un-initiated TLS is the same protocol you are using whenever you go to a secure website.  The problem is that no one takes the time to turn it on.  Much less implement it fully.  From a sys-admin point of view it's pretty much the same as putting a cert on your website.  Generate a CSR send it in to your signer of choice - get the signed cert back and install.  Done.

If everyone would just do this the benefits to mankind are huge.  Couple this with adding SPF data in your DNS and Bob's your uncle.  90% less spam and no more worries about emailing - well - anything.

Currently sending an email is pretty much akin to sending postcards.  You wouldn't put your credit card number (or anything else private) on a postcard would you?  Would you?

Of course there are methods of sending email securely but they take some doing and know-how (hint PGP or GPG/GnuPG are the best).  If everyone did TLS no more worries.  Come on folks, get with the program!

In the meantime here is my PGP/gpg/GnuPG key.  Send me some secure mail...

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.10 (GNU/Linux)

mQILBEEtergBEADZmkXCi8lMKZaGcTiUwtaS6mNwxtvGPJqEGjsOnH/iaYw9zMgJ
uTVToTYad5zBYitIGDwKUqsKen3TrkL1LL9wIVv3iLUzY6sXA+P2VmF5ebTJeonC
CR78BIav0MmFS6Y1J7i/6wxHvLzaCRLVGtw+Cy6ksRapWL9OoCAl8OwHh+zY/7k0
nnqfe6CGAw+mdkfxM2t+xa6eUSuJEmYH4jVCGT7/iFTZZaqp8n8uY9C5IXdJdQPv
d9AdHpmD9MVpLZkyeeKQ4aYcuI25+3ABDZm3lw93xUW76M1vLjwV8mFDomN1x2PV
+jLk//44kw+uV7Q8Kd8aIrcwsQH//+WWfFoxY8QLLOsPySTEZWQ+HJRbReqSyJS+
RpxXY7RAyDJoki1TVBt7crR/veKjdcaERSKlbDrEiAwM4o6pO6A0Wkf8u3kVQM7e
6M1a+6vYfeQrB7u6OP3tZJOlt+e+EUiIEvL2hhh36H06SAUZwFrBAzshGfwqUrQG
Wi5whntZbsPjWIb+34b0+f45cKcSTZ4vy/xsg2JjCyi1s8qw9OkhWzyvIYAHMJve
NpPIB4nUlZESp5Pnb1WBXjj/uXpqHy0/lXVAdE5H0PQD5qZK/Hx9NcYMIHxeh6q2
Akw7ZbVqkshIUqGY9d001n4AD/NRhDi+MUjZqQF2FnJ6TAMehMiDleiOJwAGKbQe
U2hhd24gTWFtbW9uIDxzaGF3bkBtYW1tb24udXM+iQJBBBABAgArBQJLxI/EGRhs
ZGFwOi8va2V5c2VydmVyLnBncC5jb20FHgEAAAAEFQgJCgAKCRAp/0oPm0I4bQP9
EADR29imKFDk0lHdE3fr6X7EMCgUa8d8e/0Vd33dLHydcdiEFbFdzzhy/OmQHr1W
fTY1wIGxi/7JRdiE7szkhy/CDfG8OAzdH+/wBzxuv5odP1567abys9ZF4X68wihC
Wy73ZIIGqSIBVO3w0kKC4Yufp9vMiKP0v3153swpPJbhUcemnoflg1utpMmYYYKZ
iz9YBqSKB0Z/QydsD5LMDtggRDu9+2fXTXnboHZzEAmjeOppLVcuY5xHxCvQDS9O
S2ydRKkTYCSSdFUNmnuGyUzXjj8G7krMzGGz27cZRQ2NevnRcjPtJkhe4XwLmJZg
+GShP00Hr1mpoqdI/XqhUN1MuLkUVlNQkcwqKNt7V9pvkERHllQTVHIz0hl7YlYN
oyix2Q6CBlO9mwXz55BJdfBHa9H/PmsfOuwfJqxFHbExsPMTFWNva5topwNLl2uh
hBNDCPFZ9a8PTbjETmst9BG8xzpLKzATd7RXIIgXKlf+4NtxnjpCbFpnYNkmPLLR
6/DDd83P79fMa81SU4pOQqQzy1Vi+oSeeOLl106/xDkXIKzz+XuLnCdNlgnOp/lz
T9q6vTQwQq0yhEFyBULDO4Id9tmLbeW9Bvy48t/l9c8GmRZ5F8SNwweyYAd3h3x7
Nulpgwuk8O2FIcG8Rz18p4IQ6PA4bwW2cf21Gk1SWnC/EokBIgQQAQIADAUCTOrO
+QUDABJ1AAAKCRCXELibyletfBibB/9yGb5Uw0aCU9qX3e1cvnuhZOvmSN3578JO
KNLLIEG9dNi0wbaNd51mt/8LnSHMqGammjYWdLFsuyTPOKBG3DkHUSRf97mtnQws
ka6kFdb4rdHY9J1zdhvZOC4ZIr3HA6kiMLKXfJJ7eao/3P+DnjO087wQOfOIHWN7
FBXpprzw5Sra/h6bPkKo4XPOnOGhvPZdKVtZUr3ftccq/5mbm7qlDKtqHAetVPOo
Ef9YSOS0or9kzCUbOTwNT46ogNcTuPlewqfP+fmcxc4TgBAHEe+T1DmcXuge8vV7
kQnvKWxv+EpA+GPS7pr4IpKTv77DC1kMLfc7beAkpedDRBC+DwUK
=ESN2
-----END PGP PUBLIC KEY BLOCK-----

No comments: